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(54) Creation and distribution of digital documents 

(57) A method and apparatus to create, distribute, 
sell and control access to digital documents using se- 
cure cryptographic envelopes. An envelope is an aggre- 
gation of information parts, where each of the parts to 
be protected are encrypted with a corresponding part 
encryption key. These encrypted information parts 
along with the other information parts become part of 
the envelope. Each part encryption key is also encrypt- 
ed with a public key, and these encrypted part encryp- 
tion keys are also included in the envelope. The enve- 
lope also includes a list of parts where each entry in the 
list has a pan: name and a secure hash of the named 
part. The list is then signed with a secret key to generate 
a signature, which is also included in the envelope. The 
signature can be verified using a second public key as- 
sociated with first secret key, and the integrity of any in* 
formation part In the envelope can be checked by com- 
puting a second hash and comparing It with the corre- 
sponding hash in the list of parts. Also, the information 
content of any encrypted part can only be recovered by 
knowledge of a second secret key corresponding to the 
public key that was used to encrypt the part encryption 
keys. 
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Description 

This invention is related to a method (or the creation 
and distribution, of digital documents in particular using 
the methods and techniques of secure cryptographic 
envelopes. The invention also relates to a method for 
the sale and controlled access of digital documents us- 
ing the same methods and techniques. 

Digital documents have numerous advantages over 
paper-based, analog documents. They are easier to 
create, distribute, and duplicate. However, these advan- 
tages also make it difficult to protect their associated in- 
tellectual rights from infringements. Nevertheless, digit- 
al documents will replace paper-based documents as a 
vehicle for the distribution and sale of information in the 
future. 

An important distinction between our work and Ref. 
2 is that In our disclosure the part encryption key is car- 
ried in the cryptographic envelope and is encrypted un- 
der a public key. Whereas in Ref.2-the distributed data 
only contains an identifier of the encryption key. The en- 
cryption key is stored at a server and is retrieved upon 
the presentation of the key identifier Therefore with Rel. 
2 it is necessary to maintain a key database at the server 
necessitating a measure of trust between a buy server 
and a document server 

Pretty Good Privacy (PGP) is a public-key based 
system lor sending secure e-mail. The body of the e- 
mail is encrypted using an IDEA algorithm (see, e.g.. 
Ref.1). and the encryption key is encrypted using the 
public key of the intended recipient. Both the encrypted 
e-mail text and the encrypted encryption key are sent. 
The recipient uses his secret key to recover the encryp- 
tion key, which is then used to recover the plain text 

There is described a method for the creation, distri- 
bution, and sale of digital information using the methods 
and techniques of secure cryptographic envelopes. 
Cryptographic envelopes use modem cryptographic 
techniques (such as encryption and authentication) to 
secure document parts from unauthorized reading and 
tampering. 

The process described in this disclosure albws 
parts of a cryptographic envelope to be bought by a user 
and their informational contents released in a secure 
and controlled manner. Additional processing of the 
pans are introduced to deter piracy. Furthermore, the 
use of public-key technology makes cryptographic en- 
velope technique a convenient, secure, and self-con- 
tained means of distributing digital information. 

Super dl trlbutl n 

The basic model for information distribution as- 
sumed h re is super distribution. (See R 1.5 for a mor 
in-depth discussion on Ih subject). Th basic idea is 
that digital documents (or parts) can be freely distribu- 
tion over the Int met. by radio or television signals, by 
cable, by satellite, by local area networks, by diskettes. 



by CD-ROMs, and by BBS as long as each document 
is encrypted. Assuming that the encryption process is 
sufficiently secure, the only way a user can have access 
to the content is to purchase the necessary PEKs (part 
5 encryption keys) that are typically orders of magnitudes 
more compact than the documents they decrypt. 

Super distribution is a powerful concept because it 
decouples the problem of information distribution into: 

10 (1 ) the distribution of bulk data; and 

(2) the controlled release of content through the re- 
lease ot PEKs. 

This invention extends on this basic concepl and 
is introduces the techniques of cryptographic envelopes 
tor content distribution and sale. Furthermore, the con- 
cepts and techniques are generalized to handle arbi- 
trary forms and conditions on the access to and use of 
digital documents. The generalization allows crypto- 
20 graphic envelope to be used as a basis for designing 
and implementing distributed access control of digital 
documents. 

This invention makes it unnecessary to maintain 
such a key database at the server and furthermore al- 
2S tows a cleaner separation of trusts between the Docu- 
ment Server (place where contents are encrypted) and 
the Buy Server (place where document encryption keys 
can be obtained). 

According to one aspect of the of the invention there 
30 is provided a method of providing access to content data 
in a cryptographic envelope, said method comprising: 

a) transmitting a request from a user to a server, 
said request being a request to access a part of said 

35 cryptographic envelope, said request comprising at 
least an encrypted part encryption key which is a 
public key encryption of a key used to encrypt said 
part; 

b) transmitting a response, in response to said re- 
40 quest, from said server to said user, said response 

being a transformation of said encrypted part en- 
cryption key said transformation being generated 
by: 

45 decrypting said encrypted part encryption key 

using a secret key associated with said public 
key, and 

encrypting said part encryption key using a sec- 
ond public key; and 
so decrypting said transformed key using said se- 

cret key into said part encryption k y, wherein 
said e tect d part is decrypt d into clear text 
using said part encryption key. thereby provid- 
ing access to said user. 

55 

According to a second aspect of the invention th re 
is provided a method of creating a cryptographic enve- 
lope, which can be distributed arbitrarily to a plurality of 
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users, said envelope being a digital document which is 
an aggregation of information parts, said method com- 
prising: 



part encryption keys, said encrypt d parts, and 
those of said information parts which have not 
been encrypted; and 



a) encrypting one of said information parts with a 
part encryption key to produce an encrypted part, 
which is included in said envelope; 

b) encrypting said part encryption key with a first 
public key to produce an encrypted part encryption 
key, which is included in said envelope; 

c) creating a list of parts that are included in said 
envelope, each entry in said list comprising a part 
name and a secure hash of said named part, said 
list also being included in said envelope; and 

d) signing said list with a first secret key to produce 
a signature, which is included in said envelope; 

wherein the integrity of said list can be checked 
using a second public key associated with said first se- 
cret key to verify said signature, and wherein the integ- 
rity of any one part of said envelope can be checked by 
computing a second secure hash of said one part and 
comparing said second hash with its corresponding 
hash in said list, and wherein the information content of 
said encrypted part is protected from disclosure and can 
only be recovered with eaid part encryption key, and 
wherein said pan: encryption key can be recovered by 
decryption of said encrypted part encryption key using 
a second secret key corresponding to said first public 
key. 

According to a third aspect of the invention there is 
provided a communications network having a server 
with electronic access to a plurality of terminals, a meth- 
od of authorizing access to selected content data, said 
cryptographic envelope being created by: 

a) creating a cryptographic envelope, which can be 
distributed arbitrarily to a plurality of users, said en- 
velope being a digital document which is an aggre- 
gation of information parts, said method compris- 
ing: 

(i) associating a part encryption key for each of 
said parts to be protected, wherein one of said 
parts contains said selected content data; 

(ii) encrypting each of said parts to be protected 
with its associated part encryption key; 

(iii) encrypting each said pan encryption key 
with a public key to form an encrypted part en- 
cryption key for each of said part encryption 
keys; 

(iv) creating a list of parts, each entry in said list 
containing a part name for one of said parts, a 
s cur hash for said one part; and 

(v) signing said list with a secret key to produce 
a signatur .wherein said cryptographic enve- 
lope is the aggregation of: 

said signature, said list, said encrypted 



s b) When a user in possession of a copy of said cryp- 
tographic envebpe desires to access said selected 
content data said access being given by: 

(i) transmitting a request from said user to a 
io server, said request being a request to access 

a part of said cryptographic envelope, wherein 
latter said part contains said selected content 
data, said request comprising at least an en- 
crypted part encryption key which is a public 
'5 key encryption of an encryption key used to en- 

crypt latter said part; 

(ii) transmitting a response, in response to said 
request, from said server to said user, said re- 
sponse comprising a transformation of said en- 

20 crypted part encryption key in said request, said 

transformation being generated by: 
decrypting said encrypted part encryption k y 
in said request using a secret key associat d 
with said public key of step b (1), encrypting 

26 said part encryption key in said request using 

a second public key; and decrypting said trans- 
formed key using said secret key associated 
with said second public key into said part en- 
cryption key in said request, wherein said se- 

$o lected part is decrypted into clear text using 

said part encryption key in said request, there- 
by providing access to said user. 

Accordingly, a method of creating a cryptographic 

35 envelope is provided which can be distributed arbitrarily 
to any number of users, where only authorized users 
have access to the clear text content of the secure in- 
formation parts. With this invention, each of the informa- 
tion parts is encrypted with a corresponding part encryp- 

40 tion key to generate an encrypted information part. Each 
part encryption key is then encrypted with a public key. 
A list of parts that are included in the envelope is also 
created, and each entry in the list has a part name and 
a secure hash of the named part The envelope, then, 

45 includes the encrypted information parts, the unencrypt- 
ed information parts, the encrypted part encryption keys 
and the list of parts. Finally, the list of parts is signed 
with a secret key to produce a signature, and this sig- 
nature Is also included in the envelope. The integrity of 

so the list can be checked using a second public key asso- 
ciated with th s cret key that was us d to. sign th list. 
The integrity of any one information part can be check d 
by computing a e cond hash on the part and comparing 
th s cond hash with the corresponding hash for the 

ss part in th list Finally the information content of the n- 
crypted part is protected from disctosur and can only 
be recovered with a part encryption key, and knowledge 
of a secret corresponding to a public key is necessary 
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to obtain an unencrypted part encryption key. The latter 
unencrypted key is then used to generate clear text from 
the information part. 

In order to promote a fuller understanding of this 
and other asp .cts of the present invention, an embodi- s 
ment will now be described, by way of example only, 
with reference to the accompanying drawings in which: 

FIG. 1 gives an overview of the five steps of a cryp- 
tographic envelope process. The main entities in- 10 
volved in the process are the Document Server (DS) 
100, the Buy Server (BS) 102, the decryption fin- 
gerprinting and watermarking module (OFWM) 1 03, 
and user personal computer (UPC) 101; 
FIG. 2 shows the structure of a typical cryptographic rs 
envelope. The minimal elements are an encrypted 
pan 203 and its associated encrypted part encryp- 
tion key (PEK) 202, list of parts 209, and signature ' 
of list of parts 208; 

FIG. 3 shows the structure of a bill of materials 20 
(BOM), which has a list of parts 209. Each entry of 
the table contains the part name 302, e.g., •Ab- 
stract - , and the MessageDigestS (MOS), that is, a 
secure hash, of the named part 301, e.g. 
•13ADBF77F...'. The MD5 of the list is computed *$ 
and the resultant hash is signed using the OS's ee- 
cret key to produce a digital signature 208. The list 
209 and the signature 208 form the BOM; 
FIG. 4 shows a typical price matrix. The columns 
shows the discount factor (or various membership 30 
categories (402, 403. 404. 405). and the rows show 
the quantity discount (406, 407, 408, 409). A sam- 
ple formula for computing the price of the rMh copy 
and the total price of n copies is as shown 401; 
FIG. 5 shows a Buy Request Message (BRM) 500. 3$ 
Included in the BRM are the encrypted PEKs (202, 
211 ), encrypted fingerprinting and watermarking irv 
structions 205, terms and conditions 206, and BOM 
207. Items 202, 205. 206, 207, and 211 are copied 
from the cryptographic envelope 200 (see Figure 2) 40 
The other parts of the BRM (501-505) are general- 
ed at the UPC; and 

FIG. 6 shows a Buy Server Response (BSR) 600. 
The Buy Server (BS)translates the PEKs toproduce 
translated PEKs (602, 603) which only the OFWM 45 
103 can decrypt. The fingerprinting and watermark- 
ing Instructions are decrypted, customized, and re- 
encrypted, and the result 604 can be decrypted only 
by the DFWM. The terms and conditions In the BRM 
(500, Figure 5) are also evaluated and may produce so 
updated or transformed terms and conditions 605. 
Th actual purchase price 601 is comput d by ap- 
plying th appropriate discounts on the base price. 



and own d by the respective business partners in the 
enterpnse and are operat d by trusted personnel inside 
a glass house. 

It is also assumed that' there isnl much security at 
the UPC (User Personal Computer) 101. since it be- 
longs to the user, except that it has a relatively small and 
secure DFWM (Decryption Fingerprinting and Water- 
marking Module) 103. where security is provided in soft- 
ware or through tamper-resistant hardware. 

Overview of Steps 

An overview of the processing steps is as follows 
(See Figure 1.) 

Step 1 Cyptographic Envelope Creation 

Step 2 Cryptographic Envelope Distribution 

Step 3 User-Initiated Buy Request 

Step 4 Buy Server Response 

Step 5 Opening of Cryptographic Envelope 

Cryptographic Envelope Processing Steps 

Each of these processing steps is described in 
greater detail. 

Step 1: Cryptographic Envelope Creation 

The first step is the creation of a cryptographs n- 
velope. See 200 of FIG. 2. The creation event is usually 
done off-line by the content provider because of antici- 
pated needs lor a collection of digital documents to be 
super distributed. 

Alternatively, it could be triggered by a user request. 
In this case the cryptographic envelope would be creat- 
ed specifically for the user, and the cryptographic enve- 
lope may contain certain information specific to the user 
or the request. Moreover, rf it's anticipated that there will 
be similar future requests by other users, additional in- 
formation might be included in the cryptographic enve- 
lope, and the cryptographic envelope is cachedto allow 
future similar requests to be fulfilled more efficiently. 

Cryptographic Envelope Parts 



R lerring to Figure 1 , one of the key advantages of $s 
the cryptographic nv lop process is security. It is as- 
sumed that the BS (Buy Server) 102 and the DS (Doc- 
ument Server) 100 are secur *. E.g.. they are managed 



A cryptographic envelope Is a grouping of informa- 
tion parts. See 201-211 of FIG. 2. Some of the infor- 
matbn parts are encrypted while others are In clear text. 
The cryptographic envelope process is compatible with 
a wide variety of grouping technologies (e.g. zip. tar. and 
Ihemor obj ct-ori nted approaches of OpenDoc Ben- 
to and Microsoft OLE). The requirem nte on the group- 
ing method is minimal: 

(1 ) the parts can be aggr gated into a unit suitable 
for distribution and the parts can later b individually 
retriev d; and 

(2) there should be means of associating different 
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parts, e.g., by naming, pointers, or indices. 

Information parts ar ol two types: document (201 
and 203) and control {202, 204 - 211). Document parts 
are the 'contents*. Some examples of document parts 
are abstracts, table of contents, figures, tables, and 
texts. They could also be portions of an executable pro- 
gram, a library of subroutines, software modules, or ob- 
ject components. 

Referring to Figure 2, document parts may be en- 
crypted (203). Encrypted document parts 203 are often 
the Valuable contents* to be purchased by the user (e. 
g., a section of a book, a high resolution JPEG picture, 
or an MPEG 6tream). Unencrypted parts are the teas- 
ers' 201 (e.g., reviews of the book by others, the table 
of content, the abstract, or a low resolution JPEG pic- 
ture). The purpose of the unencrypted parts is to allow 
theuserto 'preview - , •sample', or "browse - the contents 
of a cryptographic envelope before the actual purchase. . 

Some pre-processing, such a6 compression and in- 
sertion of special string patterns, may be applied to doc- 
ument parts. Compression reduces storage. Other pre- 
processing are modification to the document parts to fa- 
cilitate the fingerprinting and watermarking of document 
parts by the DFWM. 

Control parts are the metadata needed to support 
the functions and the process model of a cryptographic 
envelope. There are two main functions: authenticity 
and confidentiality. The functions of the cryptographic 
envelope are not tampered with. This authentication 
function is achieved by using digital signatures. The 
confidentiality function is achieved by encryption (e.g.. 
using DES or IDEA). The basics of these encryption and 
authentication techniques are well known in the art and 
can be found in any modem text on cryptography (e.g, 
see Ref.1 ). All control parts are authenticated and some 
may be encrypted, if necessary. 

Examples of control parts are price matrix (See Fig- 
ure 4,400) and fingerprinting and watermarking instruc- 
tions 205 for the postprocessing of the document parts. 
The post-processing of the document parts is performed 
by the DFWM, when the cryptographic envelope is 
open. Fingerprinting and watermarking are examples of 
post-processing, they mark document parts in a way to 
deter piracy. 

Referring to Figure 4. The price matrix 400 de- 
scribes the pricing structure for the purchase of the doc- 
ument parts, e.g., volume discount for buying multiple 
copies, discount for club membership, or corporate dis- 
count. An example formula 401 to compute the pur- 
chase price of n copies of a document. (Note, th price 
discount factor may also be time depend nt, in which 
ca e the columns of the price matix (402 • 405) are time- 
limited special offers instead of club memb rship). 

Referring to Figure 2, terms and conditions 206 on 
the purchase and the use of the document parts can also 
be included in the cryptographic envelope. They may be 
included as document parts (in which case Ihey will be 



mad visibl to the user) or included as control parts (in 
which case they will be evaluated at the Buy Serv r (BS) 
102 and possibly again at the user's personal computer 
(UPC) 101). The document pans contain some textual 
5 information, and the control parts may contain some 
program (e.g., written in a scripting language such as 
Perl (Ref.4) implementing the terms and conditions. 
(Note: The fingerprinting and watermarking instructions, 
and the price matrix. We list them explicitly for clarity). 

10 

Confidentiality and Authenticity 

We now describe a method in which confidentiality 
can be achieved. Parts of value are encrypted using a 

is DES (Data Encryption Standard) algorithm (e.g., see 
Ref.1). Different parts are encrypted using different 
PEKs (part encryption keys). These keys are chosen 
randomly and independently. 

There are many ways of generating a random en- 

20 cryption key. One way is to use random or a pseudo- 
random number generator to produce a random string, 
which is used as the key. More details on these schem 
can be found in (Refs.1 and 3) 

Each PEK is encrypted using the public key of a BS 

25 (Buy Server) 1 02 and the resultant encrypted PEK 202 
(Figure 2) becomes a control part in the cryptographic 
envelope. (Note: a PEK may be encrypted using differ- 
ent BS public keys and all theses encrypted PEKs in- 
cluded in the cryptographic envelope.) 

30 There are many ways of ensuring the authenticity 
of a cryptographic envelope and its parts. We now de- 
scribe one such method. Every cryptographic envelope 
has 8 special control part called BOM (Bill ol Materials) 
207. The BOM is consist of two parts: 

35 

(1 ) a list of parts 209; and 

(2) a digital signature 2QQ. 

We apply a secure hash function, MessageDigestS 

40 (MD6) (see, e.g. , Ref . 1 for details), to each part included 
In a cryptographic envelope and create a list Referring 
to Figure 3, each entry in the fist contains the part name 
or reference 302 and a secure hash 301 of the informa- 
tion part corresponding to the pan: name. (E.g., In the 

45 case of a file-based grouping, list of parts would be a 
file containing the file names of all the files and their cor- 
responding hash results). 

The list is then digitally signed with a secret k y 
known only to the OS (Oocument Server) 1 00. There are 

so many ways of cfigrtalfy signing a oocument (see, e.g.. 
R f.1). On way is to compute th MD5 (or any other 
secur hash) of the list of parts and to encrypt th re- 
sultant hash using the secret key (to produce a signa- 
ture) 208. The list of parts and th signature together 

ss are referred to as the BOM 207. Note, that only the pub- 
lic key of the OS is needed to verify the auth ntlcity of 
the BOM. 

Authenticity of the cryptographic envelop is 
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checked by dec/ypting the signature using the public 
key of the DS and comparing that with the MD5 of list of 
parts. If the two match, then the list of parts has not been 
tampered with. The authenticity of oidividual parts can 
also be checked by computing the MD5 of the each part s 
and by comparing the result its corresponding entry in 
the list. Therefore, the BOM 207 ensures the integrity of 
a cryptographic envelope and all its parts. 

Cryptographic Envelope fe Self-contained 



content 201. 



An important feature of cryptographic envelope is 
that it is selNcontained in the following sense. Only the 
public key of a OS is needed to verify the authenticity of 
the cryptographic envelope. Because the encrypted 
PEKs (202, 210. 211, see Figure 2) are with the crypto- 
graphic envelope, only the secret key of a 8S is needed 
recover the content. Moreover, different Document 
Servers can generate cryptographic envelopes using 
only the public key ol the BS; 

no other communications between BSs and DSs 
are needed. 

Cryptographto Envelope Creation Steps 

We now summarize the processing eteps In the cre- 
ation of acryptographic envelope. (See Figure 2) 

1-a Assemble information parts to be included in the 
cryptographic envelope. 

1-b Apply optional processing steps (e.g.. compres- 
sion, pre-fingerprinting, and pre-watermarking) to 
parts. Keep sufficient state information of these 
processing steps to undo the operations later. 

1-c Generate random PEKs (part encryption keys) 
202. one for each part to be encrypted. 

1-d Encrypt document parts with their respective 
PEKs to form the encrypted parts (203, 204, 205), 
which are included in the cryptographic envelope. ' 

1-e The PEKs are then encrypted using the public 
key of a BS to form encrypted PEKs (202, 21 0, 21 1 ), 
which are included in the cryptographic envelope! 
Encrypted PEKs and their corresponding encrypted 
parts are associated. 

1-f Also encrypt the instruct tons and other state in- 
formation from Step 1-b using some random PEKs. 
Th PEKs are encrypt d with a public key of th BS 
Both encrypted parts (203, 204, 205) and encrypt d 
PEKs (202. 21 0, 21 1 ) are placed in the cryptograph- 
ic envelope. 

1-9 Include in the cryptographic envelope clear text 
parts such as teasers', abstracts, and a table of 
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1-h Include terms and conditions such as finger- 
printing and watermarking instructions 205 and 
pricing matrix 206. Encrypt any parts or sub-parts if 
necessary (and include their encrypted PEKs) As 
before associate encrypted parts with their encrypt- 
ed PEKs. 

U Create a list 209 of information parts, listing all 
the parts assembled and computing a secure hash 
for each of the parts listed. 

1-J Create a signature 208 for BOM 207 by digitally 
signing the list, e.g., computing the secure hash of 
the list and encrypting it with the DS secret key. The 
BOM 207 (list 209 and signature 208) are added to 
cryptographic envelope. 

20 See Figure 2 for details on possible cryptographic 
envelope structure. 

Step 2; Cryptographic Envelope Distribution 

25 Once a cryptographic envelope is created, it can b 
distributed by any means, e.g., sending over the Inter- 
net, by radio or television signals, by cable, by satellite 
by CO-ROMs, and by BBS. Security of distribution is not 
needed. Cryptographic envelopes may be copied du- 
30 plicated, and shared between users. In fact, if s our an- 
ticipation that •down-stream" distribution of crypto- 
graphic envelope (i.e.. copying cryptographic envelope 
by fnends) is a cost-effective means of distributing cryp- 
tographic envelope. Lastly, cryptographic envelope may 
35 be stored in any servers without any security require- 
mem on the server. 

Step 3: Ueer-fnttlated Buy Request 



40 



45 



This step.is often preceded by a user browsing the 
plain text teaser* 201 portion ol a cryptographic enve- 
lope. A user who is interested in the cryptographic en- 
velope content would have to buy the necessary PEKs 
from the BS. (See Figure 1.) 

Graphical User Interface 



The browsing of the cryptographic envelope is per- 
formed with the help of a QUI such as a modified web 
so browser that understands the cryptographic envelop 
structure. First, th modified brows r must be able to 
ch ck the integrity of the cryptographic nv top . Th 
ueerienotrfi dofanytamp ring of the cryptographic en- 
v tope parts through the integrity check, Next, the 
brows r should be abl to display the clear texts in the 
cryptographic envelope, e.g., display the abstracts and 
table of contents. Finally, referring to Figures 2 and 5 
the browser must the able to extract the necessary parts 
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from the cryptographic nv lop 200 to construct a BRM 
(Buy Request Message) 500. 

Prf rR gietratt n 

We assume that there was a prior registration step 
carried out by the user so that the user is recognized by 
the BS. For example, the user could register with a trust- 
ed third party. 

For example, the registration may involve a phone 
call from the user to a registration center which will issue 
an account number to the user. The account number is 
then forwarded to all the BSs. Alternatively, the registra- 
tion center can digitally 6lgn the account number, in 
which case, no update in the BSs is needed. A BS can 
just verify the account number by checking the signa- 
ture. 

After registration, the user is issued certain creden- 
tials (e.g., account number and other membership Infor- 
mation). A credential s a document digitally signed by 
a trusted third party which contains information such as 
an account number, affifiations, or rights held by the user 
also, as an example, the third party could issue to the 
user certain 'book club* membership credentials that 
entitles him to discounts off the list price. 

Secure DFWM 

More specific to our methods fs that we assume, as . 
a result of registration, a secure DFWM (103, Figure 1) 
(decryption fingerprinting watermarking module) is in- 
stantiated at the UPC. 

The DFWM is responsible for decrypting the parts 
and at the same time applying fingerprinting and water- 
marking on the decrypted parts. Watermarking puts vis- 
ible markings in the document in such a way that is hard 
to erase and does not affect the perusal of the docu- 
ment. Fingerprinting are "invisible* markings in the doc- 
ument and are therefore hard to remove. 

For more information on fingerprinting and water- 
marking techniques, see application serial number 
08/494,61 5 filed on June 23, 1 995, and assigned to the 
same assignee of the instant application. 

Instantiation of DFWM 

There are various Implementations of a secure 
DFWM. The simptiest is based on the public key tech- 
niques, where the DFWM securely generates and 
stores a secret key within the DFWM security boundary. 
For example, the DFWM could use a ps udo-random 
numb rg n ratortocr ate a public-secret key pair. The 
DFWM s cret key is stored within th DFWM and the 
public key is known to the outside. Th r gistrat ion proc- 
ess allows th trust d third party to c rtify th DFWM 
public key. (Se e.g., Ref.l on public key certification 
process). The DFWM secret key is the onty secret infor- 
mation kepi in th DFWM module. 



Security of DFWM 

The DFWM could be a piece of software running in 
a physically secured module (e.g. smart cards) or run- 

s ning in the UPC environment (which is unsecure). In the 
former case, security is achieved through the physical 
tamper resistance of the packaging. Current packaging 
technology can provide sufficient security to the DFWM 
for all practical purposes. 

10 we will focus on the latter case, where we do not 
assume the physical security of DFWM. This Is the more 
interesting case, since the availability of physical secu- 
rity only enhances the security of DFWM. 

Without secure hardwares, the security of DFWM 

T5 cannot be guaranteed. In many practical cases, we can 
achieve sufficient security using well-known software 
techniques (e.g., code-obscuring techniques well 
known to virus writers). 

However, one of key advantages of the process de- 

20 scribed in this disclosure is that even if the DFWM is 
compromised, the exposure is limited. The user cannot 
unlock a document part that hadnl been purchased 
(since the PEK is not available). The buy transaction is 
secure since it must go through a secure BS. 

2B If a DFWM is compromised (e.g., the DFWM seer t 
key is exposed)* the only possible toss is that a docu- 
ment that a user purchased is not properly fingerprinted 
and watermarked. However, the security risk is not en- 
tirety different from the possibility of the user erasing the 

30 markings from the document 

Buy Request Transaction 

We now describe the buy request transaction in 

ss greater detail. 

Through the Graphical User Interface (GUI), the us- 
er is prompted with a list of articles contained in the cryp- 
tographic envelope. The user may browse the relevant 
abstracts for more information. The user may also know 

to the list price of the articles. If the user still wants to buy 
the articles, the user would Initiate a buy-request 
through the GUI) resulting in a BRM (Buy Request Mes- 
sage) (see 500, Figure 5) being sent to the BS 102. 

45 User Authentication 

Before the buy request can be completed, the sys- 
tem may want to authenticate the user. There are many 
well known techniques for user authentication by th 
so system. Eg., one such technique (simitar to what is 
used in Pretty Good Privacy Ref.3) i to store the user 
private key encrypted on the disk drive of the UPC. 

The us r is prompted for his password, which is 
used to decrypt the private key. The private k yisus d 
to digitally sign or certify a buy-related message and is 
erased at th end of each session. 



13 



EP0798 892 A2 



Envir omental variables 

Environmental variables are information about the 
user environment or information about the UPC (e g 
locale lime, machine type, operating system name! 
etc.). In contrast, user credentials are informatfon about 
(he user. 

Environmental variables are ol two types: secure 
and insecure. Secure variables are verified and digitally 
s.gned. They can.be checked and signed either by the 
8S (during registration) or generated and sighed by the 

Insecure variables are generated by the UPC They 
are not verified or signed They are included solely for 
informational purposes. Throughout this document en- 
vironmentai variables will mean both. 

Buy Request Message 

Referring to Figure 5, the BRM 500 contains the fol- 
lowing information copied or extracted from the crypto- 
graphic envelope (200, Figure 2): 

3.1 BOM of the cryptographic envelope 207 

3.2 List of articles to buy 501 

3.3 PEKs associated with the list of articles andoth- 
er control parts (202 and 211 ) 

3.4 Termsand conditions (such as price matrix, etc.) 
206; and the following information copied or extract- 
ed from the user environment, from the DFWM, or 
by the user: 

3.5 List of user credentials (e.g., membership.and 
discount cards) and user authentication related in- 
formation 502; 

3.6 Environmental variables (e.g., date and time, lo- 
cale, DFWM or machine hardware 10) 503; 
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. 3< Explicrt agre ment by th us r to the terms and 
condrtions 208 of the purchase (e.g., list price 
promise not to redistribute); 

jW Prompting the user to enter a password for au- 
thentication. (As a result some user authentication 
related information is generated and included in the 
BRM); 

3-* Generation of BRM 500 by the GUI; and 

3-f Sending BRM to BS. 

Note: a BRM can be viewed as a special type of cryp. 
tographic envelope ~ namely a "Buy Request' crypto- 
graphic envelope. 

Stop 4: Buy Server Response 

The BSR (Buy Server Response) is sent upon th 
receipt of a BRM. We now describe in detail the actions 
teken by a BS (Buy Server) prior to the sending of a 
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When a BS receives a BRM, it verifies the BOM to 
check the authenticity of the control parts. It also checks 
the authenticity of the DFWM public key, the user cre- 
dentials, and the usor authentication related informs- " 
ton. The user may have an account with the BS from 
the prior registration step), in which case, the appropri- 
ate amount is debited from the user account (after ap- 
plying any discounts the user is entitled to) 
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3.7 The DFWM public key 504. 



Standard cryptographic techniques, such as en- 
cryption and authentication, may be applied to the BRM. 
One way of authenticating the BRM is to compute the 
MD5 of the entire BRM, and using the secret key ol the 
DFWM, encrypt the resultant MD5 to produce a signa- 
ture 505, which is added t the end of the BRM. 

We now summarize the steps leading to the gener- 
ation of a BRM: 



45 



SO 



crypto- 



3-a Perusal of th cl ar t xt portions of th 
graphic nv lop through GUI; 

3-b Selection of information parts of cryptographic 
envelope to be purchased; 



ss 



Evaluation of Terms and Conditions 

The primary purpose of terms and conditions 206 
included in the cryptographic envelope (and also in the 
BRM) is to ensure that the user has meet the require- 
ments described by the terms and condrtions needed to 
complete the purchase. The BS checks that the user has 
met the requirements by evaluating (executing) the 
terms and conditions. The result of the evaluation de- 
termines whether the purchase can be completed If the 
result Is favorable, then the rest of the steps continue- 
otherwise, an error message Is included in the BSR 
When the result is favorable, the actuat purchase pric 
« also computed using the formula 401 given with the 
price matrix (400). 

K y Translation 

On oftheactionep rformedbyth BS on a BRM 
ts key translation. As m ntioned In Step 1, PEKs (part 
encryption keys) are encrypted using th public key of 
a BS. The BS decrypts the encrypted PEKs using its 
secret key. After decrypting the encrypted PEKs. the BS 
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re-encrypts the PEKs using th public k y of th DFWM 
public key so that only the DFWM can retrieve PEKs. 
This is the key translation step. 

Customized Fingerprinting end Watermarking 

Another set of actions performed by the BS is the 
customization ol the fingerprinting and watermarking in- 
structions. As mentioned in Step 1 these instructions are 
encrypted using the BS public key and carried in the 
cryptographic envelope as control parts. The BS would 
first decrypt the instructions and then include in the in- 
structions, information about the user (e.g., user name, 
membership number) and information on the transac- 
tion (e.g., purchase date, license restrictions, transac- 
tion ID). These instructions are then encrypted using the 
DFWM public key. (The DFWM checks tor these en- 
crypted fingerprintingand watermarking instructions to 
be present before decrypting the document.) 

Transformation of Term a and Conditions 

Other aspects related to the restrictions on the use 
of the contents are included in the BSH. The terms and 
conditions included in the BRM may be augmented or 
modified (e.g., the terms may have changed since the 
cryptographic envelope was created). The resultant 
terms and conditions could be some simple plain texts 
stating the restrictions, terms and conditions on the use 
of the documents. Or they could be executable instruc- 
tions, objects, and agents that enforces the terms and 
conditions. All these are included in the BSR 

Buy Response Steps 

Referring to Figure 6, we now summarize the steps 
taken by the BS, from receiving a BRM to sending a 
BSR. 

4-a Receiving a BRM. 

4-b Check the authenticity of BRM (by checking 
BOM), verify user credentials, verify user authenti- 
cation related information, verify DFWM public key, 
check environmental variables. 

4-c Evaluate terms and conditions, using as Inputs 
(from BRM) the user credentials, the price matrix, 
and environmental variables and (from BS) user in- 
formation in database and additional environmental 
variables. The outputs from the evaluation of th 
terms and conditions are: 

(a) whether th user is allowed acc sstothe 
parts; and 

(b) the actual price for purchasing the parts 
601. 



4-d Ch ck if us r is allowed access and the user 
has sufficient credit. If not, abort and send an error 
BSR. 

5 4-e Translate PEKs. (Decrypt PEKs using BS pri- 
vate key and reencrypt PEKs using DFWM public 
key.) Include them in BSR (602, 603). 

4- 1 Customize fingerprinting and watermarking in- 
fo structtons. (Decrypt instructions, include user spe- 
cific and transaction-related information in instruc- 
tions. Encrypt modified instructions using DFWM 
public key). Include them in BSR 604. 

>5 4-g Include transformed terms and conditions and 
other restrictions on the use of the documents in 
BSR 605. 

4~h Send BSR to user. 

20 

A BSR can be viewed as a special type of crypto- 
graphic envelope — namely a 'License Cryptographic 
Envelope'. Again standard cryptographic techniqu s 
such as encryption and authentication can be applied to 
*5 protect the privacy and authenticity of a BSR 606. (See 
e.g., Ref.1) 

Step 5: Opening of Cryptographic Envelope 

30 This is the final step. A precondition for this step is 
the receipt of a BSR from the BS. After receiving a BSR, 
the user can open the cryptographic envelope at his 
convenience. 

The BSR is the 'key* to unlock the cryptographic 

3S envelope. The content of the BSR is usable only to the 
specific DFWM since the PEKs are all encrypted under 
the DFWM public key. Referring to Figure 6, the steps 
involved in the opening of a cryptographic envelope are 
as follows. 

40 

5- a The DFWM checks to ensure the authenticity of 
the BSR 606. The opening continues only if the BSR 
authentication is successful. 



s-b The user may optionally be prompted with the 
updated licensing terms and conditions 605 in the 
BSR. The opening continues only if the user agrees 
to the terms and conditions. 

so &-c The DFWM authenticates and decrypts the 
translated PEKs (602. 603) and the customized fin- 
gerprinting and watermarking instructions (604). 
The opening continues only if the authentication is 
successful. 

55 

6-d Using the decrypted PEKs, the DFWM decrypts 
the corresponding encrypted parts of the crypto- 
graphic envelope (203. 205). 
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5- The DFWM applies the appropriate watermark- 
ing and fingerprinting instructions 604 to the de- 
crypted documents. (The fingerprinting and water- 
marking are customized to the user, providing ad- 
ditional deterrence against unauthorized distribu- s 
lion). 

5-f The resultant decrypted documents are re- 
leased to the user, outside of the DFWM security 
boundary. io 

The cryptographic envelope process can also be 
used to implement efficient, secure, distributed access 
control for highly sensitive data (such as patient medical 
records) or databases, in general. is 

In summary there is described a method and appa- 
ratus to create, distribute, sell and control access to dig- 
ital documents using secure cryptographic envelopes. 
An envelope is an aggregation of information parts, 
where each of the parts to be protected are encrypted *0 
with a corresponding part encryption key. These en- 
crypted information parts along with the other informa- 
tion parts become part of the envelope; Each part en- 
cryption key is also encrypted with a public key, and 
these encrypted part encryption keys are also included « 
in the envelope. The envelope also includes a list of 
parts where each entry in the list has a part name and 
a secure hash of the named part. The list is then signed 
with a secret key to generate a signature, which is also 
included in the envelope. The signature can be verified 30 
using a second public key associated with first secret 
key, and the integrity of any information part in the en- 
velope can be checked by computing a second hash 
and comparing it with the corresponding hash in the list 
of parts. Also, the information content of any encrypted 35 
part can only be recovered by knowledge of a second 
secret key corresponding to the public key that was used 
to encrypt the part encryption keys. 
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Claims 

1. A method of providing access to content data in a 
cryptographic envelope, said method comprising: 

a) transmitting a request from a user to a server, 
said request being a request to access a part 
of said cryptographic envelope, said request 
comprising al least an encrypted part encryp- 
tion key which is a public key encryption of a 
key used to encryot said part; 

b) transmitting a response, in response to said 
request, from said server to said user, said re- 
sponse being a transformation of said encrypt- 
ed part encryption key, said transformation be- 
ing generated by: 

decrypting said encrypted part encryption 
key using a secret key associated with said 
public key, and 

encrypting. said part encryption key using 
a second public key; and 

decrypting said transformed key using said 
secret key into said part encryption key, 
wherein said selected part is decrypted into 
clear text using said part encryption key, 
thereby providing access to said user. 

2. A method of creating a cryptographic envelope, 
which can be distributed arbitrarily to a plurality of 
users, said envelope being a digital document 
which is an aggregation of information parts, said 
method comprising: 

a) encrypting one of said information parts with 
a part encryption key to produce an encrypted 
part, which is included tn said envelope; 

b) encrypting said part encryption key with a 
first public key to produc an encrypted part n- 
cryptionk y, which is Included in said env lope; 

c) cr ating a list of parts that are included in said 
envelope, each entry in said list comprising a 
part name and a secure hash of said named 
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part, said list also being included in said enve- 
lope; and 

d) signing said list with a first secret key to pro- 
duce a signature, which is included in said en- 5 
velope; 

wherein the integrity of said list can be 
checked using a second public key associated with 
said first secret key to verify said signature, and io 
wherein the integrity of any one part of said enve- 
lope can be checked by computinga secondsecure 
hash of said one part and comparing said second 
hash with its corresponding hash in said list, and 
wherein the information content oi said encrypted 1S 
part is protected from disclosure and can only be 
recovered with said part encryption key, and where- 
in said part encryption key can be recovered by de- 
cryption of said encrypted part encryption key using 
a second secret key corresponding to said first pub- 20 
lie key. 

3. A method as recited in claim 2, further comprising 
the step of modifying selected ones of said parts of 
said document by insertions, deletions or changes 
of selected words or bits in said selected parts and 
maintaining state information associating each 
modified document part with its modifications to re- 
cover a respective unmodified document. 

30 

4. A method as recited in claim 3. wherein said modi- 
fications are applied to said selected ones of said 
parts before said encryption of said part, wherein 
said state information is encrypted using a third part 
encryption key, which is encrypted with a third pub- 35 
lie key. 

5. A method as recited in claims 2. 3 or 4, wherein said 
cryptographic envelope contains a computer pro- 
gram, which is to be executed at a server and the «o 
result of said execution determines subsequent op- 
erations by said server. 

6. A method as recited in claim 5, wherein said pro- 
gram describes the terms and conditions on the ac- 45 
cess of said information parts in said cryptographic 
envelope, and wherein said execution determines 
whether access to said information parts is granted. 

7. A method as recited in claim 5, wherein said pro- 50 
gram comprises instructions to modify each docu- 

m nt part, wh rein ach part is modifi d by ins r- 
tions, deletions, or changes of sol ct d words or 
bits in each part and wh rein state information as- 
sociating each modified document part with its mod- ss 
ifications is maintained to recover a r sp ctivo un- 
modified document 



a In a communications network having a server with 
electronic access to a plurality of t rminals, a meth- 
od of authorizing access to selected content data, 
said cryptographic envelope being created by: 

a) creating a cryptographic envelope, which 
can be distributed arbitrarily to a plurality of us- 
ers, said envelope being a digital document 
which is an aggregation of information parts, 
said method comprising: 

0) associating a part encryption key for 
each of said parts to be protected, wherein 
one of said parts contains said selected 
content data; 

(ii) encrypting each of said parts to be pro- 
tected with its associated part encryption 
key; 

(iii) encrypting each said part encryption 
key with a public key to form an encrypt d 
part encryption key for each of said part en* 
cryptbn keys; 

(Tv) creating a list of parts, each entry in 
said list containing a part name for on of 
said parts, a secure hash for said one part; 
and 

. (v) signing said Gst with a secret key to pro- 
duce a signature.wherein said crypto- 
graphic envelope is the aggregation of: 

said signature, said Gst, said encrypted 
part encryption keys, said encrypted parts, and 
those of said information parts which have not 
been encrypted; and 

b) when a user in possession of a copy of said 
cryptographic envelope desires to access said 
selected content dala said access being given 
by: 

(i) transmitting a request from said user to 
a server, said request being a request to 
access a part of said cryptographic enve- 
lope, wherein latter said part contains said 
selected content data, said request com- 
prising at least an encrypted part encryp- 
tion k y which id a public key encryption of 
an encryption key used to encrypt latter 
said part; 

(ii) transmitting a response, in respons to 
saidrequ st, from said serv r to said user, 
said response comprising a transformation 
of said encrypted part encryption key in 
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said request, said transformation being 
generated by: 

decrypting said encrypted part encryp- 
tion key in said request using a secret * 
key associated with said public key of 
step b (t ), encrypting said part encryp- 
tion key in said request using a second 
public key; and 

10 

decrypting said transformed key using 
said secret key associated with said 
second public key into said part en- 
cryption key in said request, wherein 
said selected part is decrypted into is 
clear text using said part encryption 
key In said request, thereby providing 
access to said user. 

20 
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